New analyses reveal Nimda's tenacity

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
Security consultants stressed on Friday that, while the spread of the disruptive Nimda worm has slowed, many companies are having difficulties rousting the malicious program from their networks. (For more information, see "Help and HowTo: Nimda") "It's an awfully insidious little bastard," said Mike Scher, senior research consultant with network protection company Neohapsis. "You clean it off of one segment of the network and have to make sure it doesn't come back. It's almost like fighting a fire." After successfully preventing Nimda from entering its network, Scher's client -- a Fortune 500 company -- picked up the worm from an employee working from home. After that, the program spread quickly throughout the corporation's worldwide offices. "This is a huge organisation, so there are lots of infections," said Scher, who had been working 48 hours to clean the digital infestation from the network. "It's a terrible pain to get off." The tenacious worm also caused several Internet service providers to take drastic steps to block customers from spreading the worm and overloading their networks with traffic. XO Communications acknowledged on Friday that the company severed almost a quarter of its customers' Web servers from the Internet in an attempt to halt the deluge of data produced by the worm. "Many of our customers are small businesses," XO Communications spokeswoman Jenna Dee said. "They bring in an IT person to set up their network and don't have a full-time technical employee. Those types of businesses are the most susceptible to these attacks." Another Internet service provider, DSL.net, completely cut off hundreds of its customers after it became apparent that their computers had been infected by the worm, according to customers' reports. DSL.net did not immediately respond to requests for comment. The Nimda worm hit so quickly -- peaking within six hours -- and caused so much havoc that accurate analysis of the worm has been delayed. For example, earlier this week, antivirus software firm Symantec had originally classified removal of the Nimda worm as "easy", but 24 hours later changed that evaluation. The latest information shows the Nimda worm's extensive replacement of key files and programs on infected PCs and its use of Windows file sharing to spread across local area networks have made it very hard to clean out. Nimda -- which is "admin", the shortened form of "system administrator", spelled backwards -- started spreading early Tuesday morning and quickly infected PCs and servers across the Internet. Also known as "readme.exe" and "W32.Nimda", the worm is the first to use four different methods to infect not only PCs running Windows 95, 98, Me and 2000, but also servers running Windows 2000 and Windows NT. The worm spreads by four different routes. Microsoft has posted an extensive list of patches and advisories to combat the worm. The worm originally spread quickly by broadly scanning local networks and the Internet for Web servers running Microsoft's Internet Information Server software that are vulnerable to one of two well-known flaws. First, if the server has already been compromised by the Code Red II worm, then Nimda uses that backdoor to copy itself to the server as a file named "admin.dll." For all other IIS servers, the program attempts to use the "Web server folder traversal" vulnerability discovered in October 2000 to copy the file "admin.dll" to the server. Once the file is copied to the computer, the worm executes it and infects the new victim. On such servers, the worm creates a "guest" account with administrative privileges, copies itself to any network drives, makes the C: drive publicly accessible and appends a script to HTM, HTML and ASP files. The files will attempt to upload a copy of the worm to the computer of anyone who views a Web page hosted by the infected computer using a browser with JavaScript enabled. The worm also deletes the keys in the registry that set the security preferences for the computer and also causes itself to be run at startup. The ability to infect others through viewing a Web page is the Nimda worm's second path of infection. The snippet of JavaScript added to each Web file on an infected server will cause the worm, renamed "readme.eml," to upload from the server to the surfer's computer. The worm will run automatically on PCs using unpatched versions of Microsoft's Internet Explorer 5.5 SP1 or earlier. On any browser with JavaScript enabled, the worm's script will cause the browser to try to upload the code but will first ask the PC user's permission. PCs can also be infected through the worm's third mode of transmission: email. On infected computers, the Nimda worm runs its own mail service and sends email to addresses in Windows address book as well as those culled from the machine's browser cache, which stores elements of recently viewed Web pages. The email appears to have an attached WAV file, but in reality uses an old MIME (multipurpose Internet mail extensions) vulnerability to automatically run the worm once the email is viewed in the mail client's preview plane. Even on computers that are not vulnerable to the security flaw, the attachment causes the Outlook and Outlook Express email programs to open a dialogue box asking the user for permission to open the file. If the worm infects a PC through either the Web browser or email, Nimda acts much like it does on servers. In addition, the worm adds a "load.exe" file to the Windows System directory, appends itself to many .exe, .eml and Word document files, and replaces common applications such as WordPad, WinZip32 and HyperTerminal with a copy that executes the worm. In addition, the worm places copies of "Riched20.dll" -- the program that is the workhorse text editor for Word, WordPad and other editing programs -- in multiple places on every accessible hard drive. Whenever a program that uses Riched20.dll opens, that also executes the worm. This ability to spread copies of itself throughout corporate networks by using shared drives is the fourth way the worm infects. Using the network-sharing mechanism, the Nimda worm spreads fast and makes extermination very difficult, said Vincent Gullotto, director of security software maker Network Associates' antivirus emergency response team. "While you are cleaning one area of the network, it is coming back behind you and reinfecting the computers," he said. Network Associates, Symantec and other security companies have tools to help system administrators clean their systems. Yet even if companies do completely eradicate the worm from their networks, Nimda will be out there for a long time, said Jensenne Roculan, incident analyst for SecurityFocus.com's ARIS Incident Analysis Team. Roculan points out that Code Red and its variant still account for some 30,000 infections worldwide. "Code Red is still going strong because of the number of unpatched systems on the Web," she said. "If that is any indication, Nimda should be around for a while." Analyses of the Nimda worm can be found at CERT, SecurityFocus.com, Neohapsis and most antivirus companies' Web sites. See the Viruses and Hacking News Section for the latest headlines. See the Net Crime News Section for the latest on hacking, fraud, viruses and related issues. Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum. Let the editors know what you think in the Mailroom. And read other letters.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

bootlegger

Make that 13 people now - I got refused today at Manchester airport. I thought I was up to date on this legislation - I knew of the EU ruling from...

3 hours ago by bootlegger on UK airport body scans will not be opt out
tinycg

Don't forget to check out apps like GoodReader or SlideShark either, they're indispensible for people on the go in presentation situations. Best...

6 hours ago by tinycg on Four top iPad apps for people on the move
TerryRK

Well it seems there is something a number of us agree on. Why is the Ubuntu Unity launcher so ugly? I thought perhaps it was something to do with...

10 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

20 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

1 day ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

1 day ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

1 day ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

1 day ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

2 days ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

2 days ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

2 days ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

2 days ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

2 days ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

2 days ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

2 days ago by bdantas on A tale of two distros: Ubuntu and Linux Mint